On August 27, 2026, the U.S. District Court for the Northern District of California ruled that the Department of Defense's designation of Anthropic as a "national security supply chain risk" was unlawful, vacating the designation and related orders. Judge Rita F. Lin found that the action retaliated against Anthropic for criticizing the government, violating the First Amendment, and that the failure to provide advance notice or an opportunity to respond violated the Fifth Amendment as well. While the preliminary injunction issued in March had granted temporary relief based on the likelihood of success on the merits, this latest ruling is a final judgment on the merits after review of the administrative record.

The line the court drew is clear. The Defense Department retains discretion to choose AI vendors that align with its policies and to shift away from Anthropic to another supplier. But if it seeks to exclude a U.S. company it has clashed with over contract terms using the same mechanism reserved for national security "adversaries," it must meet the statutory threshold of danger and follow proper procedure. The record the government submitted could support neither.

AD

Three Actions Vacated

The challenged actions unfolded in three layers. On February 27, President Donald Trump directed all federal agencies to permanently halt use of Anthropic's technology. That same day, Defense Secretary Pete Hegseth ordered the supply chain risk designation and announced a policy barring contractors and suppliers doing business with the U.S. military from any commercial dealings with Anthropic—even for purposes unrelated to military contracts. Then, on March 3, the Defense Department formally finalized the designation under 10 U.S.C. § 3252, notifying Anthropic the following day.

The final relief order issued on August 27 permanently enjoins the implementation, enforcement, and effect of these actions. It also orders the defendant agencies involved in carrying out the measures to rescind related guidance and notices and take necessary steps to ensure they are not reinstated. The designation under 10 U.S.C. § 3252 was vacated, as was the Secretary's directive requiring defense-related companies to cut off all commercial dealings with Anthropic. Orders and sanctions imposed by agencies that implemented the measures—including the Defense Department, Treasury, and State Department—were also vacated. However, the same relief did not extend to interim measures taken by HHS and the Commerce Department. The Department of Veterans Affairs, the SEC, and NASA were likewise excluded.

Anthropic did not prevail on every claim. Its argument that the presidential directive violated separation of powers by exceeding executive authority was rejected, and the government also won on claims involving agencies that took no action or that limited themselves to interim measures. Still, the core legal basis for the supply chain risk designation and the secondary exclusion from commercial dealings collapsed on the merits. The government's request for a seven-day stay of the permanent injunction was also denied.

A Four-Page Memo Written After the Fact Couldn't Explain "Sabotage"

The supply chain risk contemplated under 10 U.S.C. § 3252 concerns the danger that an adversary might sabotage national security systems, insert malicious functions, or interfere with their operation. To invoke this authority, the government must consult with relevant procurement officials, make a written determination that narrower measures cannot mitigate the risk, and notify Congress of the basis for its action.

Yet the central document in the government's administrative record laying out the rationale for the designation was just four pages long—and it was drafted after two of the three actions had already been made public. The document initially claimed that Anthropic had "backdoor" access to Claude instances deployed in defense systems, posing a risk that Anthropic could shut down the model or alter its guardrails. As litigation proceeded, it became undisputed that Anthropic has no such capability to access deployed models in that manner.

The actual mechanics of Claude Gov also didn't match the government's account. While the defense-oriented model includes a limited monitoring feature that logs risk scores for prompts, Anthropic cannot view those scores. There is no intervention capability, and Anthropic cannot remotely alter the model's behavior. The usage policy at issue was a contractual restriction—Anthropic had no technical means of enforcing it, nor any way to directly observe how the Defense Department was actually using Claude.

During litigation, the government shifted its emphasis, arguing that AI models are "black boxes" whose internal workings cannot be fully explained, and that harmful behavior could be introduced in future updates. But that risk is not unique to Anthropic. The court found no basis for inferring a future intent to covertly sabotage models from Anthropic's open assertion of its usage terms.

The timeline in the administrative record further undermined the stated rationale. Just three days before the action, Secretary Hegseth had suggested designating Claude as an essential resource under the Defense Production Act. Immediately after the designation was finalized, the Defense Department continued contract negotiations and told Anthropic it was "very close" to an agreement. In April, discussions on government collaboration involving a new model, Mythos, also moved forward. The court concluded that such conduct was inconsistent with treating Anthropic as a supplier posing a sabotage risk.

AD

Technical Controls Conflated with Contract Terms

The dispute traces back to contract negotiations for GenAI.mil that began in the fall of 2025. The Defense Department sought a clause allowing Claude to be used for "any lawful purpose." While Anthropic significantly loosened its previous restrictions, it declined to permit two specific uses: large-scale domestic surveillance of Americans, and fully autonomous weapons systems that select and engage targets without human involvement. Anthropic has explained that current frontier AI lacks the reliability to safely operate fully autonomous weapons, and that large-scale surveillance threatens fundamental rights. This is Anthropic's own position—not a safety standard for military AI generally that the court has endorsed.

Three distinct layers of control need to be separated in this negotiation:

Control Layer What Was Confirmed in Claude Gov Relationship to This Dispute
Model Training Alignment shapes output tendencies Built into the model itself, not remote post-deployment control
Runtime Monitoring Limited feature logs risk scores Anthropic cannot view or intervene; cannot alter model behavior
Usage Policy Contractually restricts use cases The two exceptions fall here; not technically enforceable

What concerned the Defense Department was future model updates and trust in the supplying company. But the direct subject of negotiation was the usage agreement. Linking the two would require demonstrating a concrete capability or indication that harmful functions could be introduced into future updates. The administrative record contained no such evidence.

The Defense Department's AI strategy document, dated January 9, 2026, helps explain why this conflict arose. The department set a future procurement standard requiring the ability to deploy the latest models within 30 days of public release, and directed that a standard "any lawful purpose" clause be inserted into AI service contracts within 180 days. In other words, the policy sought to accelerate model updates while stripping away any usage restrictions imposed by supplying companies. The court did not rule on the merits of this policy itself—it rejected the administrative decision to recast a rejection during contract negotiations as a supply chain sabotage risk.

Winning the Case Doesn't Guarantee a Return to Defense Contracts

The final order does not compel the Defense Department to use Claude. So long as it complies with statutory and constitutional requirements, the department remains free to end its relationship with Anthropic and switch to another AI company. Indeed, even for Anthropic—whose technology has been used by U.S. intelligence and defense agencies since 2024, and which secured a contract worth up to $200 million over two years in July 2025—this legal victory does not guarantee future business. That "$200 million" figure represents a contract ceiling, not an amount actually paid.

Nor is the litigation fully resolved. A related case is pending before the D.C. Circuit Court of Appeals, concerning a separate designation made under a different supply chain security statute, 41 U.S.C. § 4713. That court denied Anthropic's request for an emergency stay on April 8, but acknowledged that the issues were novel and difficult and that irreparable harm was possible, sending the case to expedited review. Oral arguments were held on May 19, but the California district court's ruling does not directly resolve this separate case. The permanent injunction itself could also still be challenged on appeal.

What remains the key consideration for AI procurement going forward isn't whether a vendor asserted its contract terms. It's who holds post-deployment access rights, in what environment updated versions are verified, and whether usage restrictions are enforced through contract terms or runtime technical controls. If the government seeks to invoke supply-chain risk statutes again, the deciding factor will be whether it can document a vendor's specific capability for sabotage or tampering—and explain, on the record, why narrower measures such as contract termination would be insufficient.